PT-2026-96218 · Inventree+1 · Inventree+1
CVE-2026-61749
·
Published
2026-09-21
·
Updated
2026-09-21
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
InvenTree versions prior to 1.4.0
Description
Privileged staff users with permissions to author report or label templates can trigger the WeasyPrint report rendering process to retrieve resources selected by an attacker via HTTP, HTTPS, or local file URI schemes. The
HTML(string=html).write pdf() path lacks a restricted url fetcher, and the attach to model=True setting stores the original generated PDF. This allows for the recovery of fetched local files or internal HTTP response bodies from embedded attachments, leading to full-read server-side request forgery (SSRF), arbitrary local file disclosure including application credentials, and potential compromise of superuser accounts.Recommendations
Update to version 1.4.0.
Exploit
Fix
Information Disclosure
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Inventree
Weasyprint